2FA by Email with Onetime-Passcode

2FA should also be possible by Email with Onetime-Passcode.

many customers don't have a company smartphone and therefore can't set up 2FA at the moment, so i can't enforce 2FA, although i would find this extremely useful and it would significantly increase security.

Since there is currently no self-servivce 2FA reset prozess, it would also be very useful to have the email address as another factor besides the authenticator app to establish a 2FA process with multiple factors. So if you then lose your authenticator app, you can still log in via onetime-email-passcode.

Let's take a look at Microsoft 365's MFA, there it is possible for years.

Furthermore, the onetime-email-passcode could be automatically activated for the customer accounts without a setup process, using directly the login address for the onetime-passcode.

Best regards

Ingo

Please authenticate to join the conversation.

Upvoters
Status

In Review

Board

Core Web App

Subscribe to request

Get notified by email when there are changes.